An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.
History

Thu, 17 Jul 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Pribai
Pribai privategpt
CPEs cpe:2.3:a:pribai:privategpt:0.5.0:*:*:*:*:*:*:*
Vendors & Products Pribai
Pribai privategpt
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.
Title Stored XSS in imartinez/privategpt
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-03-20T10:09:21.980Z

Updated: 2025-03-20T18:55:55.477Z

Reserved: 2024-08-20T19:38:40.578Z

Link: CVE-2024-8029

cve-icon Vulnrichment

Updated: 2025-03-20T17:51:16.674Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-20T10:15:39.870

Modified: 2025-07-17T15:56:07.520

Link: CVE-2024-8029

cve-icon Redhat

No data.